Detecting SQL Injection Stored Procedures Vulnerability in the Web Application using Fuzzing Technique


연구 분야: Databases



학회: 2024 IEEE Long Island Systems, Applications and Technology Conference (LISAT)


초록

Web Application is part of our lives. Among many vulnerabilities, SQL injection is one of the most prevalent and exploited vulnerabilities in web applications. A SQL Injection is possible using insufficient validation of user input and metacharacters that are interpreted unintentionally on the database tire. As a result, Stored Procedures (SP) need to be used to protect the database. SP are small programs on the database that execute from the web application. However, not all SP can mitigate SQL injection. Hence the security team tried different tools like Veracode, Burp Suite to find SQL injection issues. This paper introduces a fuzz-testing platform for detecting and validating SP SQL injection vulnerabilities on web applications. We compare the detection techniques based on related works and improve the detection technique for stored procedure vulnerability.


Author Profile
Md Arif Ahmed

Department of Computer Security Technology Farmingdale State College State University New York

정보 없음

📄 논문 정보

발행 연도 2024년
인용수 69
출판 국가
사이트 IEEE
좋아요 수 0

연관 논문 목록 (420건)